jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 vulnerabilities
CVEs whose affected-version data names the jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
CVE-2026-93576High· 7.5A flaw was found in Netty netty-codec-smtp
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this…
CVE-2026-93560High· 7.5A flaw was found in the Netty STOMP codec
A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite dec…
CVE-2026-93575High· 7.5A flaw was found in Netty's MqttDecoder
A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Re…
CVE-2026-93572High· 7.5A flaw was found in Netty's `RedisArrayAggregator` component
A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly prealloca…
CVE-2026-93563High· 7.5A flaw was found in Netty's `SmtpResponseDecoder` component
A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without …
CVE-2026-93561Medium· 6.5A flaw was found in io.netty/netty-codec-memcache
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server ca…
CVE-2026-93494High· 7.5A flaw was found in Netty's StompSubframeDecoder component
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf…
CVE-2026-89059High· 7.5PoCA flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafte…
CVE-2026-89058High· 7.4PoCA flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. Thi…
CVE-2026-81624High· 7.5Undertow is a flexible performant web server used in JBoss EAP and WildFly
Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot …
CVE-2026-19611High· 7.4A flaw was found in WildFly Elytron
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using a…